Skip to main content

Vendor archive

hasthemes CVEs

Beta · best-effort

96 CVEs tagged to vendor hasthemes6 Critical, 7 High, 83 Medium, 0 Low, 0 Unrated.

CVE-2025-68533

Published Dec 24, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WC Builder wc-builder allows Stored XSS.This issue affects WC Build…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64271

Published Nov 13, 2025

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects WP Plugin Manager: from n/a t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12493

Published Nov 4, 2025

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-11823

Published Oct 25, 2025

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-58990

Published Sep 9, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLentor woolentor-addons allows Stored XSS.This issue affects Sho…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8401

Published Jul 31, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8151

Published Jul 31, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. Thi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8068

Published Jul 31, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3775

Published Apr 25, 2025

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request For…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1802

Published Mar 20, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text'…

CVSS 6.4 · Medium
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-1527

Published Mar 12, 2025

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cros…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-1261

Published Mar 8, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, an…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-26917

Published Mar 3, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata wptemplata allows Reflected XSS.This issue affects WP T…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12599

Published Feb 11, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and includin…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12597

Published Feb 4, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to,…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24695

Published Jan 24, 2025

Server-Side Request Forgery (SSRF) vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allows Server Side Request Forgery.This issue affects Extensions For CF7: from…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-51673

Published Nov 9, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems HT Politic wp-politic allows DOM-Based XSS.This issue affects HT Pol…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51682

Published Nov 4, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor ht-builder allow…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49630

Published Oct 20, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems WP Education wp-education allows Stored XSS.This issue affects WP Ed…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9538

Published Oct 11, 2024

The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8910

Published Sep 25, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render functio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 96 CVEsPage 1 of 4